Hello by Flow
/ LEGAL

Privacy Policy

LAST UPDATED · 22 JUNE 2026

This Privacy Policy explains how Hello by Flow Communications Pvt. Ltd. ("Hello by Flow") collects, uses, stores, and shares your personal data when you use our Service. We are committed to compliance with the Digital Personal Data Protection Act, 2023 (DPDPA) in India and the EU General Data Protection Regulation (GDPR) where applicable.

1. Data we collect

Account data

  • Name, work email, password (hashed with bcrypt), workspace name, role.

KYC documents (required by DoT/TRAI)

  • Business accounts: Certificate of Incorporation, GST/PAN, authorised signatory ID.
  • Individual accounts: Aadhaar, Passport, Driving Licence, or Voter ID (front + back), address proof, optional selfie.

Service data

  • Call metadata (caller, callee, duration, direction, status), call recordings (only when explicitly enabled by the agent), SMS content, contacts you import, IVR flow definitions, analytics events.

Device & log data

  • IP address, browser user-agent, timestamps, error logs.

2. Purposes of processing (DPDPA Sec. 4)

  • To provide the Service you signed up for (lawful basis: contract performance).
  • To comply with DoT/TRAI telecom regulations, anti-fraud screening, and CAF retention.
  • To bill you and prevent payment fraud.
  • To improve product quality (aggregated, de-identified analytics only).

3. Data Principal rights (DPDPA Sec. 11–14)

You may at any time:

  • Access your personal data (Settings → Profile or write to dpo@hellobyflow.com).
  • Correct inaccurate data.
  • Erase data (subject to legal retention obligations under the Information Technology Act, 2000 and CAF rules — call detail records retained for 12 months).
  • Withdraw consent — your account is deactivated within 7 days.
  • Lodge a grievance with our DPO (see Section 8).

4. Sharing

We share data only with:

  • Sub-processors: MongoDB Atlas (database hosting, India region), AWS (storage), Twilio (carrier connectivity).
  • Law enforcement: on receipt of a lawful order under the IT Act or CrPC. We publish a transparency report annually.
  • Never with advertisers. We do not sell your data.

5. International transfers

Personal data of Indian Data Principals is stored on infrastructure located within India. Limited metadata may be processed in approved jurisdictions (Singapore, EU) under standard contractual clauses.

6. Retention

  • Account data: while your account is active + 30 days post-termination.
  • KYC documents: 5 years post-termination (DoT requirement).
  • Call Detail Records (CDR): 12 months (DoT requirement).
  • Call recordings: as long as you keep them, deleted within 7 days of account termination.

7. Security

Encryption in transit (TLS 1.3), at rest (AES-256). Annual penetration testing. SOC 2 Type II audited. Bcrypt password hashing. Brute-force lockouts. Role-based access control.

8. Grievance Officer (DPDPA Sec. 13)

Data Protection Officer: dpo@hellobyflow.com
Hello by Flow Communications Pvt. Ltd., Bengaluru, Karnataka, India.
We respond to all grievances within 30 days.

9. Children

The Service is not intended for users under 18. We do not knowingly collect data from minors.

10. Updates

Material changes will be notified via email and in-app banner 30 days in advance.

← Back to home© 2026 HELLO BY FLOW